Malware

Troj/VB-EUH removal

Malware Removal

The Troj/VB-EUH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/VB-EUH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to disable or modify Explorer Folder Options
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Troj/VB-EUH?


File Info:

name: 5916CA566B1E6074F3AD.mlw
path: /opt/CAPEv2/storage/binaries/f19b0903678e0e1d4664a6bb316a06eba1f23d8deb1565190c8608d3de7877a7
crc32: 03091AB6
md5: 5916ca566b1e6074f3ad5addcac67f45
sha1: 51e91a3d9917ec5220dc53fd05f04761b8c82e08
sha256: f19b0903678e0e1d4664a6bb316a06eba1f23d8deb1565190c8608d3de7877a7
sha512: cec5086476a0299d66ceb0cb24cb5d63391c7119cc5fcc519d2b98a4de656198108ec8c2d77b35ce57348ace609d923b65cb41c8cb5ad62304114c5009214685
ssdeep: 384:9/06wayA+1mwnA353BXR+oGfP5d/ZBHXME+l93qPAqee/w6yt/EWD+S83BXR+oGv:9MpQNwC3BEddsEqOt/hytp+x3BEJwRre
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C73D643B752C681F54A6179688387A96753FD70AF037A075160FF3F3AB39A04E91B22
sha3_384: da96049c5ffc718a14d257d0e32c9443c53b5d4a79c223663dd38b96a51cbbf67055a041838ef65922f36ae0d91a741d
ep_bytes: 68186d4000e8f0ffffff000000000000
timestamp: 2009-01-06 03:24:42

Version Info:

Translation: 0x0409 0x04b0
ProductName: Microsoft Windows
FileVersion: 1.00.0050
ProductVersion: 1.00.0050
InternalName: music
OriginalFilename: music.exe

Troj/VB-EUH also known as:

BkavW32.FamVT.ViselCPM.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.74328
FireEyeGeneric.mg.5916ca566b1e6074
McAfeeVilsel.gen.o
MalwarebytesVB.Trojan.Generic.DDS
ZillyaTrojan.Vilsel.Win32.49226
SangforWorm.Win32.VB.pro3
CrowdStrikewin/malicious_confidence_100% (D)
K7GWP2PWorm ( 004e46c61 )
K7AntiVirusTrojan ( 005640b91 )
BitDefenderThetaAI:Packer.AD53139321
VirITTrojan.Win32.Generic.AZOV
CyrenW32/VB.DS.gen!Eldorado
SymantecTrojan.Dropper
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.THB
APEXMalicious
ClamAVWin.Malware.Genpack-6989317-0
KasperskyTrojan.Win32.Vilsel.bpxe
BitDefenderTrojan.GenericKDZ.74328
NANO-AntivirusTrojan.Win32.Vilsel.cqkyek
AvastWin32:VB-AEMS [Trj]
TencentTrojan.Win32.VB.blb
EmsisoftTrojan.GenericKDZ.74328 (B)
BaiduWin32.Trojan.VB.h
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen2.50583
VIPRETrojan.GenericKDZ.74328
TrendMicroTROJ_VILSEL.AI
McAfee-GW-EditionBehavesLike.Win32.Vilsel.lt
Trapminemalicious.high.ml.score
SophosTroj/VB-EUH
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Vilsel.A
JiangminTrojan.Vilsel.dat
WebrootW32.Rimod.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Vilsel
XcitiumTrojWare.Win32.Vilsel.ALY@4bdezk
ArcabitTrojan.Generic.D12258
ZoneAlarmTrojan.Win32.Vilsel.bpxe
MicrosoftTrojanDropper:Win32/Lamechi!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Vilsel.R490586
VBA32Trojan.Vilsel
ALYacTrojan.GenericKDZ.74328
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Vilsel.AM
TrendMicro-HouseCallTROJ_VILSEL.AI
RisingTrojan.VB!1.BE89 (CLASSIC)
YandexTrojan.GenAsa!fpIOh2aUKFk
IkarusTrojan.Win32.Scar
MaxSecureTrojan.Vilsel.aly
FortinetW32/Agent.OZA!worm
AVGWin32:VB-AEMS [Trj]
Cybereasonmalicious.66b1e6
DeepInstinctMALICIOUS

How to remove Troj/VB-EUH?

Troj/VB-EUH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment